Congress mandates cybersecurity for suicide hotline—but won't fund it
H.R. 912 — 9–8–8 Lifeline Cybersecurity Responsibility Act · Filed by Jay Obernolte (R-CA) · 3 cosponsors · Introduced Feb 4, 2025 · Referred to committee
Your members of Congress
Enter a ZIP to see where your representative and both senators stood on this bill.
Looked up on this device — your ZIP is never stored on our servers.
What it does
This bill requires the 9-8-8 National Suicide Prevention Lifeline to implement cybersecurity protections and establish a reporting system for security vulnerabilities and incidents. Network administrators and local crisis centers must report cybersecurity problems to federal overseers within a reasonable timeframe, and the Government Accountability Office must study the lifeline's cybersecurity risks within 180 days.
Why we flagged it
The bill's core function is to impose cybersecurity standards and incident-reporting obligations on a federally funded suicide prevention service. It is a regulatory requirement, not a subsidy or deregulation.
What the text implies
- The phrase 'reasonable amount of time' for reporting vulnerabilities and incidents is undefined, potentially allowing delays that could leave the hotline exposed or callers' data at risk.
- The bill does not specify funding for cybersecurity improvements, only reporting requirements—crisis centers may lack resources to actually fix vulnerabilities they are required to report.
The full analysis lists 4 implications of this text.
Who stands to gain
cybersecurity consulting firms; network security software vendors; IT infrastructure providers